The gold standard of trust
乐鱼(Leyu)体育官网 helped a global auto manufacturer develop an organization-wide strategy to manage insider risk for its most sensitive data.
乐鱼(Leyu)体育官网 helped a global auto manufacturer develop an organization-wide strategy to manage insider risk for its most sensitive data.
Client
A global automotive manufacturer
Sector
Industrial manufacturing
Project
Design and delivery of insider risk management
After sensitive company data was lost during a large workforce reduction, the company鈥檚 leadership realized that its ability to successfully protect critical assets was limited and tactical, primarily focused on an IT-related detection capability. The board of directors recommended developing an organization-wide strategy to manage insider risk for its most sensitive corporate data. When internal efforts to develop a strategy proved too slow, the company turned to outside advisors for help.
Our experience-based insights tied to this client's 鈥渢rusted workforce鈥� core value demonstrated that 乐鱼(Leyu)体育官网 had the right people with specific insider risk management experience to lead the project.
Unlike other firms that were asked to provide insight into this challenge, 乐鱼(Leyu)体育官网 took a rare and altogether different approach. We convened biweekly calls designed to listen to the client, not to pitch or propose, but answering a variety of questions from multiple stakeholders, providing experience-based insights tied to the client鈥檚 鈥渢rusted workforce鈥� core value, and demonstrating that we had the right people with specific insider risk management experience. At the end of 60 days of relationship-building interaction, we were asked to lead the project鈥攚ithout an RFP.
After three months of fieldwork, 乐鱼(Leyu)体育官网 recommended an insider risk management strategy that tapped participation from multiple business functions needed to effectively drive down insider risk quickly. Also included was a three-year execution roadmap to guide continual improvement while controlling spend.
Once approved by the board, 乐鱼(Leyu)体育官网:听
1
2
Working with senior leadership to identify and agree upon the company鈥檚 most critical assets, and developing specific insider risk scenarios and the recommended prevention, detection, and mitigation controls.
听
3
Today, the company has a strategy which recognizes that risk management is not just an IT issue. It鈥檚 a multiple stakeholder challenge, requiring board oversight and participation from senior leaders across multiple business functions, along with cross-functional controls and governance.
Importantly, the new strategy helps reinforce a key corporate value: to have the most trusted workforce in the world, supporting the company鈥檚 goal to become the most trusted brand.
With our guidance:
1
The automotive manufacturer now agrees on its most important sensitive data, gaining cross-stakeholder buy in to reduce its critical data types from 500 to fewer than 10.
听
2
The company developed three categories of insider threat training鈥攄epending on employee access to sensitive data鈥攖o reinforce the importance of managing critical assets.
听
听
3
Innovation in risk management
We deliver a gold-standard strategy for managing insider risk, based on published standards, leading best practices, and听the experiences of 乐鱼(Leyu)体育官网 professionals, all integrated into a single, executable听framework to meet boardroom expectations.
A range of subject matter professionals for specific client needs
Our team includes deeply experienced cyber security professionals as well as complementary specialists. For example, we bring in organizational psychologists to conduct HR transformation, attorneys who focus on privacy laws and regulations, and professionals with law enforcement and intelligence-community backgrounds to advise the corporate security function.
Immediate impact
In addition to delivering a strategy and roadmap, we also develop client-specific scenarios and prevention, detection, and mitigation controls to drive home the immediate impact of insider threats.